Getting Data In

Splunk, monitor file changes and MD5 checksum

cyrillefranchet
Explorer

Hi all,

I'm trying to index a log file which consists of some counters. This file doesn't change a lot as counters are just incremented.

As the file size is around 1kB , I have tried to use CHECK_METHOD=entire_md5 to avoid the 256 first bytes and 256 last bytes problem. But the monitor doesn't work so well...

I'm suspecting Splunk to keep hash results somewhere , because my universal forwarder doesn't want to send the log content if the log file has already have the same content.

Maybe anyone can explain the monitor MD5 stuff more deeply? The best solution for me would be to tell Splunk to not keep those hashes.

Thank you.

Cyrille

Ayn
Legend

You most likely need to add crcSalt = <SOURCE> to your input definition. See more info in these questions/answers:

http://splunk-base.splunk.com/answers/1851/filename-was-different-therefore-source-is-not-indexed-wh...

http://splunk-base.splunk.com/answers/7824/index-monitored-file-initially

0 Karma

cyrillefranchet
Explorer

Hello Ayn,

Nice try but the file name never changes so the crcSalt is not useful. Splunk continues to retain the previous hashes.

Another idea maybe?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...